Major Facebook Breach: 50m Users Compromised

Nearly 50m Facebook accounts were compromised by an attack that gave hackers the ability to take over users’ accounts, Facebook revealed on Friday 28th Sept. The breach was discovered by Facebook engineers on Tuesday 25 September, the company said, and patched on Thursday 27th.

Users whose accounts were affected will be notified by Facebook. Those users will be logged out of their accounts and required to log back in.

“I’m glad we found this and fixed the vulnerability,” Mark Zuckerberg said on a conference call with reporters on Friday morning. “But it definitely is an issue that this happened in the first place. I think this underscores the attacks that our community and our services face.”

The security breach is believed to be the largest in Facebook’s history and is particularly severe because the attackers stole “access tokens”, a kind of security key that allows users to stay logged into Facebook over multiple browsing sessions without entering their password every time. 

Possessing a token allows an attacker to take full control of the victim’s account, including logging into third-party applications that use Facebook Login.

The security breach comes at a time of significant strife for the social media company, which has faced mounting criticism over issues including foreign election interference, the flow of misinformation, hate speech, and data privacy.
The revelation that a political consultancy linked to the US president, Donald Trump, had obtained the personal information of tens of millions of Facebook users prompted widespread concern that the company was cavalier in its approach to privacy.

“We have a responsibility to protect your data, and if we can’t then we don’t deserve to serve you,” Zuckerberg wrote in a public apology regarding the Cambridge Analytica breach.

According to Facebook, the attacker exploited three bugs that were introduced into the site’s “view as” feature in July 2017. “View as” allows users to see what their profile looks like to other users. The company does not yet know when the hack took place, but it said that it began an investigation after discovering unusual activity on 16 September.
In addition to the 50m accounts whose access tokens were taken, Facebook said that it would require 40m additional users who used the “view as” tool since July 2017 to log out of their accounts as a precaution. This will reset those users’ access tokens, protecting their accounts.

The company has notified law enforcement, the vice-president of product management, Guy Rosen, said on the conference call. Rosen said that Facebook was working with the FBI, but he did not comment on whether national security agencies were involved in the investigation.

“The investigation is early, and it’s hard to discover who is behind this,” Rosen said. “We may never know.” He did note that the scale and complexity of the hack would have required “a certain level” of expertise. Dr Lukasz Olejnik, an independent cybersecurity and privacy researcher, said: “Anyone involved in this hack knew what he was doing.” Olejnik noted that whoever discovered the vulnerabilities would likely have been eligible for a “bug bounty” payment had they disclosed the bugs rather than exploited them.

Another key area of investigation is discovering the extent to which the hackers used the access tokens. The company says it has not yet seen evidence that the hackers accessed private messages or made posts on users’ behalf, but they did attempt to access certain profile information.

Rosen did not provide any details on the location of users affected, saying only that the attack seemed “broad” and investigators had not determined whether there were particular targets. The company has notified the Irish Data Protection Commission (DPC) about the breach. 

The implementation of Europe’s General Data Protection Regulation (GDPR) meant that Facebook was required to notify data protection authorities within 72 hours if any affected users were in the European Economic Area.

The Irish DPC was critical in its initial response to the breach, tweeting: “At present Facebook is unable to clarify the nature of the breach & risk to users. We are pressing Facebook to urgently clarify these matters.

News of the hack comes at the end of a week in which many of Facebook’s Silicon Valley peers testified before the US Congress about the possibility of consumer privacy regulations.

“Today’s disclosure is a reminder about the dangers posed when a small number of companies like Facebook or the credit bureau Equifax are able to accumulate so much personal data about individual Americans without adequate security measures,” said the US senator Mark Warner in a statement. “This is another sobering indicator that Congress needs to step up and take action to protect the privacy and security of social media users.”

Facebook shares fell about 3% following the disclosure. 

Guardian

You Might Also Read:

Regulation Might Actually Protect Facebook:

ICO Fine Facebook Half A Million Pounds:

 

« US Has Devastating Cyber Weapons
NATO Can’t Agree On What A Cyber Attack Is »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

CDW

CDW

CDW is a leading multi-brand provider of information technology solutions to business, government, education and healthcare customers in the United States, the United Kingdom and Canada.

Virtual Security

Virtual Security

Virtual Security provides solutions in the field of managed security services, network security, secure remote work, responsible internet, application security, encryption, BYOD and compliance.

MixMode

MixMode

MixMode's PacketSled platform delivers network monitoring, deep forensic analysis and incident response.

IoT Now

IoT Now

IoT Now explores the evolving opportunities and challenges facing CSPs, and we pass on some lessons learned from those who have taken the first steps in next gen IoT services.

TokenOne

TokenOne

TokenOne is a Cyber Security software company that makes it easy to replace passwords, tokens and other forms of authentication with a more secure solution.

Secure Innovations

Secure Innovations

Secure Innovations is a cybersecurity firm dedicated to providing top-tier cyber security solutions for the Defense and the Intelligence Community.

Accolade Technology

Accolade Technology

Accolade provides the most technologically advanced host cpu offload, 100% packet capture FPGA-based PCIe adapters and 1U platforms available in the network monitoring and cyber security markets.

Oak Ridge National Laboratory (ORNL)

Oak Ridge National Laboratory (ORNL)

ORNL conducts basic and applied research and development in key areas of science for energy, advanced materials, supercomputing and national security including cybersecurity.

CyberTech Network

CyberTech Network

CyberTECH is a global cybersecurity, Internet of Things (IoT) and Smart City network ecosystem and incubator operator.

Aricoma

Aricoma

Aricoma are Architects of Digital. We aim to become a major player in end-to-end IT services and digital transformation in Europe.

AppTec

AppTec

AppTec is a leading software vendor in the field of Unified Endpoint Management and Mobile Security.

Privacera

Privacera

Privacera enables consistent data governance, security, and compliance across all your data services - on-premises and in the cloud - so you can maximize the value of your data.

Hexaware Technologies

Hexaware Technologies

Hexaware is an automation-led next-generation service provider delivering excellence in IT, BPO and Consulting services.

AML Global Solutions (AMLGS)

AML Global Solutions (AMLGS)

AMLGS delivers Financial Crime prevention training programmes and consultancy services encompassing Anti-Money Laundering (AML), Counter Terrorism Financing (CTF), Bribery & Corruption and Fraud.

Cisilion

Cisilion

Cisilion's mission is simple – to transform and connect business with next-generation IT infrastructure. Our expertise includes enterprise networking, security, data centre & cloud, managed services.

CypherEye

CypherEye

CypherEye is a next generation trust platform that advances the current state of Multi-factor Authentication (MFA) to enable highly secure, private and auditable cyber-transactions.